@MetatronicDave@HackingButLegal@elder_plinius imagine thinking everyone has a good GPU to run local models. for example, on my laptop i can run things like qwen 20b, but i could never run something way better like gpt oss 120b or something on at least Sonnet level
@TheRabbitPy@h4x0r_dz i tried multiple LLMs. they tend to hallucinate if you're not "helping" them. giving them a codebase and say "ok find bugs" is NOT gonna work. and as i said, most of the times, it finds fake exploit that can't be exploited, or require particular configs to get actually exploited
@TheRabbitPy@h4x0r_dz most people put claude to look at code, and don't even bother to check if it's actually right. most of the times the LPE/RCE the LLM found is probably a false positive, like a null pointer (even tho it's never null)
@S1r1u5_ completely wrong. what if I'm a red teamer with lecit intentions? and nobody would use kyc, they would lose a lot of customers and people would probably switch to other models (like Kimi, honestly underrated)
@thedawgyg makes sense. did you use sonnet or opus? i heard opus is the smartest model rn, and some people got it to write exploit code and find 0day, like someone here on X found a 0day in the windows kernel. truly fascinating lol
@dmcxblue@h4x0r_dz it is. an app shouldn't automatically open things without notifying the user. while it isn't that much of an issue since almost no one uses Whatsapp desktop AND has python installed, it's still a "vulnerability" (if it wasn't, telegram wouldn't fix it)